Intel

AIKIDO-2026-10684

astral-tokio-tar is vulnerable to UNIX Symbolic Link (Symlink) Following

UNIX Symbolic Link (Symlink) FollowingGHSA-xx64-wwv2-hcqq Published Apr 30, 2026

30

Low Risk

This Affects:

RUSTastral-tokio-tar
0.0.1 - 0.6.0
Fixed in 0.6.1
Are you affected? Scan for Free

TL;DR

In affected versions of this package, the unpack_in API could inadvertently modify the permissions of external (i.e. non-archive) directories outside of the archive. An attacker could use this to contrite a tar archive that maliciously changes directory permissions outside of its intended hierarchy. This flaw only affects directories; individual file permissions cannot be modified via it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

astral-tokio-tar is vulnerable to UNIX Symbolic Link (Symlink) Following in versions 0.0.1 - 0.6.0.

How to fix this

Upgrade the astral-tokio-tar library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform